]> git.proxmox.com Git - pve-firewall.git/blob - debian/changelog
bump version to 5.0.5
[pve-firewall.git] / debian / changelog
1 pve-firewall (5.0.5) bookworm; urgency=medium
2
3 * simulator: adapt to more flexible bridge naming scheme
4
5 -- Proxmox Support Team <support@proxmox.com> Tue, 23 Apr 2024 13:11:43 +0200
6
7 pve-firewall (5.0.4) bookworm; urgency=medium
8
9 * fix #5335: stable sorting in cluster.fw
10
11 * add configuration option for new nftables firewall tech-preview
12
13 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2024 20:04:09 +0200
14
15 pve-firewall (5.0.3) bookworm; urgency=medium
16
17 * fix resolution of scoped aliases in ipsets
18
19 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2023 10:39:28 +0200
20
21 pve-firewall (5.0.2) bookworm; urgency=medium
22
23 * fix #4556: api: return scoped IPSets and aliases
24
25 -- Proxmox Support Team <support@proxmox.com> Wed, 21 Jun 2023 19:17:19 +0200
26
27 pve-firewall (5.0.1) bookworm; urgency=medium
28
29 * fix #4556: support 'dc/' and 'guest/' prefix for aliases and ipsets
30
31 -- Proxmox Support Team <support@proxmox.com> Wed, 07 Jun 2023 16:06:10 +0200
32
33 pve-firewall (5.0.0) bookworm; urgency=medium
34
35 * switch to native versioning scheme
36
37 * build for Proxmox VE 8 / Debian 12 Bookworm
38
39 -- Proxmox Support Team <support@proxmox.com> Mon, 22 May 2023 14:43:58 +0200
40
41 pve-firewall (4.3-2) bullseye; urgency=medium
42
43 * fix variables declared in conditional statement
44
45 * fix #4730: add safeguards to prevent ICMP type misuse
46
47 -- Proxmox Support Team <support@proxmox.com> Tue, 16 May 2023 11:17:58 +0200
48
49 pve-firewall (4.3-1) bullseye; urgency=medium
50
51 * allow entering IP address with the host bits (those inside the mask) not
52 being all zero non-zero, like 192.168.1.155/24 for example.
53
54 * api: firewall logger: add optional parameters `since` and `until` for
55 time-range filtering
56
57 * fix #4550: host options: add nf_conntrack_helpers to compensate that
58 kernel 6.1 and newer have removed the auto helpers
59
60 -- Proxmox Support Team <support@proxmox.com> Fri, 17 Mar 2023 15:24:56 +0100
61
62 pve-firewall (4.2-7) bullseye; urgency=medium
63
64 * fix #4018: add firewall macro for SPICE proxy
65
66 * fix #4204: automatically update each usage of a group to the new ID when
67 it is renamed
68
69 * fix #4268: add 'force' parameter to delete IPSet with members
70
71 -- Proxmox Support Team <support@proxmox.com> Thu, 17 Nov 2022 19:53:04 +0100
72
73 pve-firewall (4.2-6) bullseye; urgency=medium
74
75 * config defaults: document that the mac filter defaults to on
76
77 * fix #4175: ignore non-filter ebtables tables
78
79 * fix enabling ebtables if VM firewall config is invalid
80
81 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Aug 2022 09:43:53 +0200
82
83 pve-firewall (4.2-5) bullseye; urgency=medium
84
85 * fix #3677 ipset get chains: handle newer ipset output for actual
86 change detection
87
88 -- Proxmox Support Team <support@proxmox.com> Thu, 04 Nov 2021 16:37:13 +0100
89
90 pve-firewall (4.2-4) bullseye; urgency=medium
91
92 * re-build to avoid issues stemming from semi-broken systemd-debhelper version
93
94 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Oct 2021 10:39:05 +0200
95
96 pve-firewall (4.2-3) bullseye; urgency=medium
97
98 * fix #2721: remove the (nowadays) bogus reject for TCP port 43 from the
99 default drop and reject actions
100
101 -- Proxmox Support Team <support@proxmox.com> Fri, 10 Sep 2021 13:00:07 +0200
102
103 pve-firewall (4.2-2) bullseye; urgency=medium
104
105 * re-set relevant sysctls on every apply round
106
107 -- Proxmox Support Team <support@proxmox.com> Mon, 21 Jun 2021 11:31:42 +0200
108
109 pve-firewall (4.2-1) bullseye; urgency=medium
110
111 * fix #967: source: dest: limit length
112
113 * re-build for Debian 11 Bullseye based releases (Proxmox VE 7)
114
115 * fix #2358: allow --<opt> in firewall rule config files
116
117 -- Proxmox Support Team <support@proxmox.com> Wed, 12 May 2021 20:32:30 +0200
118
119 pve-firewall (4.1-3) pve; urgency=medium
120
121 * fix #2773: ebtables: keep policy of custom chains
122
123 * introduce new icmp-type parameter
124
125 -- Proxmox Support Team <support@proxmox.com> Fri, 18 Sep 2020 16:51:27 +0200
126
127 pve-firewall (4.1-2) pve; urgency=medium
128
129 * revert: rules: verify referenced security group exists
130
131 -- Proxmox Support Team <support@proxmox.com> Wed, 06 May 2020 17:41:36 +0200
132
133 pve-firewall (4.1-1) pve; urgency=medium
134
135 * logging: add missing log message for inbound rules
136
137 * fix #2686: avoid adding 'arp-ip-src' IP filter if guests uses DHCP
138
139 * IPSets: parse the CIDR before checking for duplicates
140
141 * verify that a referenced security group exists
142
143 * ICMP: fix iptables-restore failing if ICMP-type values bigger than '255'
144
145 * ICMP: allow one to specify the 'echo-reply' (0) type also as integer
146
147 * improve handling concurrent (parallel) access and modifications to rules
148
149 -- Proxmox Support Team <support@proxmox.com> Mon, 04 May 2020 15:01:57 +0200
150
151 pve-firewall (4.0-10) pve; urgency=medium
152
153 * macros: add macro for Proxmox Mail Gateway web interface
154
155 * api node: always pass cluster conf to node FW parser to fix false positive
156 error message about non existing aliases, or IP sets, when querying the
157 node FW options GET API call.
158
159 * grammar fix: s/does not exists/does not exist/g
160
161 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jan 2020 19:25:49 +0100
162
163 pve-firewall (4.0-9) pve; urgency=medium
164
165 * ensure port range used for offline storage migration and insecure migration
166 traffic is allowed by default rule set.
167
168 -- Proxmox Support Team <support@proxmox.com> Tue, 03 Dec 2019 08:12:20 +0100
169
170 pve-firewall (4.0-8) pve; urgency=medium
171
172 * increase default nf_conntrack_max to the kernel's default
173
174 * fix some "use of uninitialized value" warnings when updating CIDRs
175
176 * update schema documentation
177
178 * add explicit dependency on libpve-cluster-perl
179
180 * add support for "raw" tables
181
182 * add options for synflood protection for host firewall:
183 - nf_conntrack_tcp_timeout_syn_recv
184 - protection_synflood: boolean
185 - protection_synflood_rate: SYN rate limit (default 200 per second)
186 - protection_synflood_burst: SYN burst limit (default 1000)
187
188 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Nov 2019 13:48:20 +0100
189
190 pve-firewall (4.0-7) pve; urgency=medium
191
192 * only add VM chains and rules if VM firewall is enabled
193
194 -- Proxmox Support Team <support@proxmox.com> Wed, 7 Aug 2019 10:55:06 +0200
195
196 pve-firewall (4.0-6) pve; urgency=medium
197
198 * firewall macros: add new Ceph protocol v2 port while keeping v1 port
199
200 -- Proxmox Support Team <support@proxmox.com> Tue, 23 Jul 2019 18:57:48 +0200
201
202 pve-firewall (4.0-5) pve; urgency=medium
203
204 * don't use any base path at all for calls to external binaries to make use
205 compativle with bot, /usr merged and unmerged setups
206
207 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Jul 2019 11:47:53 +0200
208
209 pve-firewall (4.0-4) pve; urgency=medium
210
211 * ebtables: remove PVE chains properly
212
213 * ebtables: treat chain deletion as change
214
215 * use /usr/sbin as base path
216
217 -- Proxmox Support Team <support@proxmox.com> Thu, 11 Jul 2019 19:40:01 +0200
218
219 pve-firewall (4.0-3) pve; urgency=medium
220
221 * Create corosync firewall rules independently of localnet~
222
223 * Display corosync rule info on localnet call
224
225 -- Proxmox Support Team <support@proxmox.com> Thu, 04 Jul 2019 15:56:11 +0200
226
227 pve-firewall (4.0-2) pve; urgency=medium
228
229 * fix systemd warning about PIDFile directory
230
231 * fix CT rule generation with ipfilter set
232
233 * pve-firewall service: update-alternative iptables and ebtables to working
234 legacy versions
235
236 -- Proxmox Support Team <support@proxmox.com> Mon, 24 Jun 2019 20:43:21 +0200
237
238 pve-firewall (4.0-1) pve; urgency=medium
239
240 * re-build for Debian Buster / PVE 6
241
242 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 22:28:55 +0200
243
244 pve-firewall (3.0-21) unstable; urgency=medium
245
246 * fix ipv6 PVEFW-reject
247
248 * fix #2193: arpfilter: CT: remove mask from net IP/CIDR to avoid
249 ebtables doing the wrong thing here
250
251 -- Proxmox Support Team <support@proxmox.com> Wed, 08 May 2019 10:09:31 +0000
252
253 pve-firewall (3.0-20) unstable; urgency=medium
254
255 * use IPCC to read config and rule files, if the are backed by pmxcfs which
256 has better handling for pmxcfs restarts
257
258 * fix #2178: endless loop on ipv6 extension headers
259
260 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Apr 2019 05:10:13 +0000
261
262 pve-firewall (3.0-19) unstable; urgency=medium
263
264 * ebtables: add arp filtering
265
266 * fix: #2123 Logging of user defined firewall rules
267
268 * fix Razor macro
269
270 * allow to enable/disable and modify cluster wide log ratelimits
271
272 -- Proxmox Support Team <support@proxmox.com> Tue, 02 Apr 2019 11:15:16 +0200
273
274 pve-firewall (3.0-18) unstable; urgency=medium
275
276 * fix #1606: Add nf_conntrack_allow_invalid option
277
278 * log reject : add space after policy REJECT like drop
279
280 * fix #1891: Add zsh command completion for pve-firewall
281
282 -- Proxmox Support Team <support@proxmox.com> Mon, 04 Mar 2019 10:27:01 +0100
283
284 pve-firewall (3.0-17) unstable; urgency=medium
285
286 * fix #2005: only allow ascii port digits
287
288 * fix #2004: do not allow backwards ranges
289
290 * add conntrack logging via libnetfilter_conntrack and allow one to enable
291 it through the firewall host configuration
292
293 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Jan 2019 16:56:17 +0100
294
295 pve-firewall (3.0-16) unstable; urgency=medium
296
297 * api/rules: fix macro return type
298
299 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Nov 2018 16:02:59 +0100
300
301 pve-firewall (3.0-15) unstable; urgency=medium
302
303 * fix #1971: display firewall rule properties
304
305 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:01:33 +0100
306
307 pve-firewall (3.0-14) unstable; urgency=medium
308
309 * fix #1841: avoid ebtable reloads when containers have multiple network
310 interfaces
311
312 -- Proxmox Support Team <support@proxmox.com> Fri, 24 Aug 2018 10:51:04 +0200
313
314 pve-firewall (3.0-13) unstable; urgency=medium
315
316 * avoid unnecessary reloads of ebtable ruleset
317
318 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Jun 2018 14:47:16 +0200
319
320 pve-firewall (3.0-12) unstable; urgency=medium
321
322 * fix deleted iptables chains not being properly detected as a change
323
324 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Jun 2018 12:01:02 +0200
325
326 pve-firewall (3.0-11) unstable; urgency=medium
327
328 * #1764: rename 'ebtales_enable' option to 'ebtables'
329
330 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2018 16:18:13 +0200
331
332 pve-firewall (3.0-10) unstable; urgency=medium
333
334 * fix #1764: handle existing ebtables rules and allow disabling ebtables
335
336 * ebtables handling can be disabled via /etc/pve/firewall/cluster.fw's new
337 ebtables_enable option.
338
339 -- Proxmox Support Team <support@proxmox.com> Tue, 29 May 2018 15:14:33 +0200
340
341 pve-firewall (3.0-9) unstable; urgency=medium
342
343 * fix creation of ebltables FORWARD rule entry
344
345 -- Proxmox Support Team <support@proxmox.com> Thu, 17 May 2018 14:41:27 +0200
346
347 pve-firewall (3.0-8) unstable; urgency=medium
348
349 * add ebtables support for better MAC filtering
350
351 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2018 14:25:41 +0200
352
353 pve-firewall (3.0-7) unstable; urgency=medium
354
355 * support distinct source and destination multi-port matching
356
357 * multi-port matching: when specifying the same list of ports for source and
358 destination require them both to match, rather than one of them, as this
359 was rather unexpected behavior
360
361 -- Proxmox Support Team <support@proxmox.com> Mon, 12 Mar 2018 14:58:08 +0100
362
363 pve-firewall (3.0-6) unstable; urgency=medium
364
365 * fix #1319: don't fail postinst with masked service
366
367 * debian: switch to compat 9, drop init scripts, drop preinst
368
369 * check multiport limit in port ranges
370
371 * build: use git rev-parse for GITVERSION
372
373 -- Proxmox Support Team <support@proxmox.com> Thu, 08 Mar 2018 13:53:11 +0100
374
375 pve-firewall (3.0-5) unstable; urgency=medium
376
377 * fix issue with disabled flag not being honored within groups
378
379 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Dec 2017 08:31:42 +0100
380
381 pve-firewall (3.0-4) unstable; urgency=medium
382
383 * fix issues with ipsets reloading unnecessarily or too late
384
385 * fix some typos in the logs
386
387 -- Proxmox Support Team <support@proxmox.com> Thu, 16 Nov 2017 11:41:56 +0100
388
389 pve-firewall (3.0-3) unstable; urgency=medium
390
391 * Fix #1492: logger: use current timestamp if the packet doesn't have one
392
393 -- Proxmox Support Team <support@proxmox.com> Tue, 12 Sep 2017 14:43:06 +0200
394
395 pve-firewall (3.0-2) unstable; urgency=medium
396
397 * Fix #1446: remove masks in case the package had previously been removed but
398 not purged.
399
400 * improve logging on errors in the firewall configuration
401
402 * forbid trailing commas in lists as iptables-restore doesn't support them
403
404 -- Proxmox Support Team <support@proxmox.com> Mon, 17 Jul 2017 15:24:40 +0200
405
406 pve-firewall (3.0-1) unstable; urgency=medium
407
408 * rebuild for Debian Stretch
409
410 -- Proxmox Support Team <support@proxmox.com> Thu, 9 Mar 2017 14:04:17 +0100
411
412 pve-firewall (2.0-33) unstable; urgency=medium
413
414 * ipset: don't allow zero-prefix entries
415
416 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 12:18:04 +0100
417
418 pve-firewall (2.0-32) unstable; urgency=medium
419
420 * improve search for local-network
421
422 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Nov 2016 06:35:08 +0100
423
424 pve-firewall (2.0-31) unstable; urgency=medium
425
426 * don't try to apply ports to rules which don't support them
427
428 -- Proxmox Support Team <support@proxmox.com> Thu, 06 Oct 2016 08:31:51 +0200
429
430 pve-firewall (2.0-30) unstable; urgency=medium
431
432 * add multicast DNS to the list of Macros
433
434 * add missing parameter descriptions
435
436 * build-depends: add dh-systemd
437
438 -- Proxmox Support Team <support@proxmox.com> Fri, 16 Sep 2016 08:53:16 +0200
439
440 pve-firewall (2.0-29) unstable; urgency=medium
441
442 * prevent overwriting ipsets/sec. groups by renaming
443
444 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 16:46:10 +0200
445
446 pve-firewall (2.0-28) unstable; urgency=medium
447
448 * use pve-common's ipv4_mask_hash_localnet
449
450 * fix allowed group name length
451
452 * make group digest stable
453
454 -- Proxmox Support Team <support@proxmox.com> Fri, 03 Jun 2016 11:01:47 +0200
455
456 pve-firewall (2.0-27) unstable; urgency=medium
457
458 * fix #972: make PVEFW-FWBR-* rule order stable
459
460 -- Proxmox Support Team <support@proxmox.com> Tue, 17 May 2016 07:59:52 +0200
461
462 pve-firewall (2.0-26) unstable; urgency=medium
463
464 * fix #988: set rp_filter=2
465
466 -- Proxmox Support Team <support@proxmox.com> Mon, 09 May 2016 10:01:28 +0200
467
468 pve-firewall (2.0-25) unstable; urgency=medium
469
470 * fix #945: add uninitialized check in lxc ipset compilation
471
472 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Apr 2016 09:58:33 +0200
473
474 pve-firewall (2.0-24) unstable; urgency=medium
475
476 * Build-Depend on pve-doc-generator
477
478 * generate manpage with pve-doc-generator
479
480 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Apr 2016 10:52:45 +0200
481
482 pve-firewall (2.0-23) unstable; urgency=medium
483
484 * use only the top bit for our accept marks
485
486 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:35:38 +0200
487
488 pve-firewall (2.0-22) unstable; urgency=medium
489
490 * Use cfs_config_path from PVE::QemuConfig
491
492 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Mar 2016 11:47:40 +0100
493
494 pve-firewall (2.0-21) unstable; urgency=medium
495
496 * added new 'ipfilter' option
497
498 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Mar 2016 09:43:39 +0100
499
500 pve-firewall (2.0-20) unstable; urgency=medium
501
502 * fix 901: encode unicode characters in sha digest
503
504 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Feb 2016 12:40:14 +0100
505
506 pve-firewall (2.0-19) unstable; urgency=medium
507
508 * Add radv option to VM options
509
510 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Feb 2016 10:24:42 +0100
511
512 pve-firewall (2.0-18) unstable; urgency=medium
513
514 * Add ndp option to host and VM firewall options
515
516 * Add router-solicitation to NeighborDiscovery macro
517
518 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Feb 2016 10:01:22 +0100
519
520 pve-firewall (2.0-17) unstable; urgency=medium
521
522 * Don't leave empty FW config files behind
523
524 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Feb 2016 14:09:24 +0100
525
526 pve-firewall (2.0-16) unstable; urgency=medium
527
528 * logger: basic ipv6 support
529
530 * add DHCPv6 macro
531
532 * add dhcpv6 support to the dhcp option
533
534 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Jan 2016 16:52:14 +0100
535
536 pve-firewall (2.0-15) unstable; urgency=medium
537
538 * fix bug #859: use $security_group_name_pattern in iptables_get_chains
539
540 * fix some regular expressions mixups
541
542 -- Proxmox Support Team <support@proxmox.com> Thu, 07 Jan 2016 16:33:23 +0100
543
544 pve-firewall (2.0-14) unstable; urgency=medium
545
546 * fix systemd service dependencies
547
548 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Nov 2015 10:52:57 +0100
549
550 pve-firewall (2.0-13) unstable; urgency=medium
551
552 * allow numeric icmp types
553
554 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Oct 2015 13:21:53 +0200
555
556 pve-firewall (2.0-12) unstable; urgency=medium
557
558 * implement bash completions
559
560 * convert pve-firewall into a PVE::Service class
561
562 -- Proxmox Support Team <support@proxmox.com> Thu, 24 Sep 2015 12:15:00 +0200
563
564 pve-firewall (2.0-11) unstable; urgency=medium
565
566 * iptables_get_chains: fix veth device name
567
568 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Sep 2015 07:54:35 +0200
569
570 pve-firewall (2.0-10) unstable; urgency=medium
571
572 * new helper: clone_vmfw_conf()
573
574 -- Proxmox Support Team <support@proxmox.com> Tue, 25 Aug 2015 06:47:49 +0200
575
576 pve-firewall (2.0-9) unstable; urgency=medium
577
578 * remove firewall config file subroutine added
579
580 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:42:51 +0200
581
582 pve-firewall (2.0-8) unstable; urgency=medium
583
584 * adopt regresion tests for lxc containers
585
586 * removed firewall code for openVZ
587
588 * Subroutine verify_rule fixed to correctly check only for "net\d+"
589 interface device names
590
591 -- Proxmox Support Team <support@proxmox.com> Wed, 12 Aug 2015 12:01:43 +0200
592
593 pve-firewall (2.0-7) unstable; urgency=medium
594
595 * added firewall code for lxc
596
597 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Aug 2015 09:21:14 +0200
598
599 pve-firewall (2.0-6) unstable; urgency=medium
600
601 * firewall ipversion comparison fix
602
603 -- Proxmox Support Team <support@proxmox.com> Tue, 04 Aug 2015 11:14:51 +0200
604
605 pve-firewall (2.0-5) unstable; urgency=medium
606
607 * add ipv6 neighbor discovery and solicitation macros
608
609 * ip6tables accepts both spellings of the word neighbor
610
611 * added Ceph macro
612
613 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:20:55 +0200
614
615 pve-firewall (2.0-4) unstable; urgency=medium
616
617 * include manual page for pve-firewall
618
619 -- Proxmox Support Team <support@proxmox.com> Sat, 27 Jun 2015 16:26:28 +0200
620
621 pve-firewall (2.0-3) unstable; urgency=medium
622
623 * use noawait trigers for pve-api-updates
624
625 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:33:06 +0200
626
627 pve-firewall (2.0-2) unstable; urgency=medium
628
629 * trigger pve-api-updates event
630
631 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:10:24 +0200
632
633 pve-firewall (2.0-1) unstable; urgency=medium
634
635 * recompile for debian jessie
636
637 -- Proxmox Support Team <support@proxmox.com> Fri, 27 Feb 2015 12:22:04 +0100
638
639 pve-firewall (1.0-18) unstable; urgency=low
640
641 * fix alias lookup
642
643 -- Proxmox Support Team <support@proxmox.com> Mon, 09 Feb 2015 09:32:03 +0100
644
645 pve-firewall (1.0-17) unstable; urgency=low
646
647 * fix restart behavior
648
649 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Jan 2015 06:45:58 +0100
650
651 pve-firewall (1.0-16) unstable; urgency=low
652
653 * use new Daemon class from pve-common
654
655 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Dec 2014 09:45:07 +0100
656
657 pve-firewall (1.0-15) unstable; urgency=low
658
659 * bug fix: load cluster conf for host rules
660
661 -- Proxmox Support Team <support@proxmox.com> Fri, 12 Dec 2014 06:33:28 +0100
662
663 pve-firewall (1.0-14) unstable; urgency=low
664
665 * do not use ipset list chains
666
667 * remove preinst script (not needed anymore)
668
669 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Dec 2014 13:42:00 +0100
670
671 pve-firewall (1.0-13) unstable; urgency=low
672
673 * fix ipset remove order
674
675 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 12:45:48 +0100
676
677 pve-firewall (1.0-12) unstable; urgency=low
678
679 * add preinst script to clear ipset from older installation (because
680 sets cannot be swapped if there type does not match.
681
682 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:59:38 +0100
683
684 pve-firewall (1.0-11) unstable; urgency=low
685
686 * bug fix: correctly set ipversion for aliases in verify_rule
687
688 * save restore commands into files to make debugging
689 easier (/var/lib/pve-firewall/)
690
691 -- Proxmox Support Team <support@proxmox.com> Fri, 28 Nov 2014 08:04:05 +0100
692
693 pve-firewall (1.0-10) unstable; urgency=low
694
695 * add IPv6 support for VMs (hostfw is IPv4 only)
696
697 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Nov 2014 07:00:29 +0100
698
699 pve-firewall (1.0-9) unstable; urgency=low
700
701 * fix max ipset name name length
702
703 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Oct 2014 16:29:34 +0200
704
705 pve-firewall (1.0-8) unstable; urgency=low
706
707 * implement permission
708
709 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Sep 2014 12:15:21 +0200
710
711 pve-firewall (1.0-7) unstable; urgency=low
712
713 * proxy host rule API calls to correct node
714
715 * always generate MAC and IP filter rules if firewall is enabled on NIC
716
717 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Jun 2014 07:12:57 +0200
718
719 pve-firewall (1.0-6) unstable; urgency=low
720
721 * ipmlement ipfilter ipsets
722
723 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jun 2014 08:37:08 +0200
724
725 pve-firewall (1.0-5) unstable; urgency=low
726
727 * remove ipsets when firewall disabled
728
729 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 08:50:18 +0200
730
731 pve-firewall (1.0-4) unstable; urgency=low
732
733 * depend on iptables and ipset
734
735 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:45:33 +0200
736
737 pve-firewall (1.0-3) unstable; urgency=low
738
739 * change dh_installinit order (register pvefw-logger before pve-firewall)
740
741 -- Proxmox Support Team <support@proxmox.com> Wed, 04 Jun 2014 06:24:21 +0200
742
743 pve-firewall (1.0-2) unstable; urgency=low
744
745 * add experimental nflog logging daemon
746
747 -- Proxmox Support Team <support@proxmox.com> Thu, 13 Mar 2014 08:27:01 +0100
748
749 pve-firewall (1.0-1) unstable; urgency=low
750
751 * initial package
752
753 -- Proxmox Support Team <support@proxmox.com> Mon, 03 Mar 2014 08:37:06 +0100
754